performance-profiling

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data sources, including application source code and diagnostic logs provided by users. This creates a surface where malicious instructions embedded within the processed data could attempt to manipulate the agent's behavior.\n
  • Ingestion points: The skill guides the agent to identify performance categories from user reports, traces, and logs, and to inspect code paths (SKILL.md).\n
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between data and potential instructions within the analyzed traces or code.\n
  • Capability inventory: The skill workflow involves identifying issues, reading reference files, inspecting code paths, and proposing fixes, which requires the agent to interpret and act on the provided data (SKILL.md).\n
  • Sanitization: The instructions do not include steps for the agent to sanitize or validate the integrity of user-supplied code or performance logs before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:54 PM
Security Audit — agent-trust-hub — performance-profiling